Credential fields that fight the password manager ================================================= Rule · bucket: mechanical · severity: warning · detector: interface-safety · since: v0.14.0 Section: Things to avoid Group: Safety at the interface Forbidden: `autocomplete="off"` on a password, a `paste` handler that blocks pasting, a one-time-code field with no `autocomplete` Instead: `autocomplete="current-password"`, `"new-password"`, `"one-time-code"`, and nothing preventing paste. Blocking the manager does not stop an attacker; it stops the reader using a long unique password, so they type a short one they can remember and reuse it everywhere. The interface decides which of those two happens.